Gartner: AI Security Spending Hits $4.8B in 2027 as Agentic Attacks Target Access Controls

Gartner forecasts the market for securing AI systems will reach $4.8 billion in 2027 — a 68.7% increase over 2026 — and climb to $7.7 billion by 2028, as enterprises confront a threat surface that traditional application security wasn’t built for. The firm splits the market into four segments: AI application security (the largest, at roughly $851 million), AI usage control (close behind at $749 million and growing 73% year over year, the fastest of the four), AI governance platforms, and AI gateways (growing 70.9%). The growth pattern tells its own story — spending isn’t concentrated in securing the models themselves anymore, it’s shifting toward controlling how employees and agents actually use AI tools day to day. Gartner’s sharpest warning is specific: by 2029, more than half of successful cyberattacks on AI agents will exploit access-control weaknesses and prompt injection, which the firm treats as a distinct new attack surface rather than an extension of conventional application security.

That framing lines up with what Gartner has been telling a different buyer inside the same enterprise. In an August 20 briefing, Gartner Director Analyst Alex Levine told CFOs to treat their first finance AI-agent deployment as a governance pilot, not an ROI showcase — arguing “early pilots are most likely to fail due to unclear controls, not poor technology,” and recommending sandboxed environments with explicit data-access limits before development even starts. OpenAI President Greg Brockman made a related point from the vendor side, writing in “The Defender’s Window” about the OpenAI–Hugging Face security incident: AI is already automating parts of real-world cyberattacks, and he had ChatGPT audit his own website in 15 minutes, surfacing 13 real misconfigurations. Read together, the forecast, the CFO guidance, and the vendor’s own admission point at the same near-term reality: agentic AI deployment now comes with a security bill attached, and the firms that treat it as a prerequisite rather than an afterthought will be the ones scaling agents safely.